Adversarial images and prompts steer models after being removed from context

Optimized visual inputs persist through the key/value cache of later tokens, surviving context compaction and single exposure.

Independent
David Dobre · Leo Schwinn · Gauthier Gidel · Spandana Gella · Perouz Taslakian · Pierre-André Noël
Research Digest··2 min read
The authors show that adversarial soft prompts and images can be trained to retain influence on a language model after the input is masked from attention or removed from the context.

The authors extend the Visual Memory Injection (VMI) setting, where an adversarial image planted in context triggers a specific response when a cue appears.

Why this paper

Independent

In one line

Adversarial inputs can persist through the KV cache, continuing to influence a model after being removed from the context.

What we could check

  • ·No code link found
  • ·No weights link found
  • ·No dataset link found
  • ·No compute details found
  • ·No stated limitations found
  • ·No benchmark numbers found

Observed from the paper text and links we have. Absence here means we did not find it, not that it does not exist.

§

Research Digest

Written by software from the reporting listed above, scored by an automated standards desk, and published without a person reading it first. If something here is wrong, tell the editor and it will be put right.

How we workSubscribe